VulnSea

Daily digest

Monday 17 November 2025

10 new CVEs this day, in line with the recent average. Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached.

10
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2025-13223High· 8.8CISA KEVPoC
10mo ago

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 5.0%via NVD
CVE-2024-44659Critical· 9.8
10mo ago

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

▾ Midnightphpgurukul · online_shopping_portalEPSS 0.41%via NVD
CVE-2025-65073High· 7.5
10mo ago

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

▾ Twilightkeystone · keystoneEPSS 0.23%via OSV
CVE-2025-62519High· 7.2
10mo ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in the main configuration update functionality of phpMyFAQ allows a privileged user with 'Configuration Edit' permissio…

▾ Twilightphpmyfaq · phpmyfaqEPSS 0.74%via NVD
CVE-2025-11681Medium· 6.5
10mo ago

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.

▾ Sunlitm-files · m-files_serverEPSS 0.39%via NVD
CVE-2025-13290Medium· 6.3
10mo ago

A vulnerability has been found in code-projects Simple Food Ordering System 1.0

A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such manipulation of the argument ID leads to sql injection. It is possible…

▾ Sunlitfabian · simple_food_ordering_systemEPSS 0.31%via NVD
CVE-2025-13289Medium· 6.3
10mo ago

A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0

A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The manipulation of the argument SubCode…

▾ Sunlit1000projects · design_&_development_of_student_database_management_systemEPSS 0.31%via NVD
CVE-2025-13263Medium· 6.3
10mo ago

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The atta…

▾ Sunlitoretnom23 · online_magazine_management_systemEPSS 0.35%via NVD
CVE-2025-13193Medium· 5.5
10mo ago

A flaw was found in libvirt

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure v…

▾ SunlitEPSS 0.12%via NVD
CVE-2025-55058Medium· 4.5
10mo ago

CWE-20 Improper Input Validation

CWE-20 Improper Input Validation

▾ Sunlitmaxum · rumpusEPSS 0.26%via NVD

Most-affected vendors

By CVEs published in the period.